Ransomware, data breaches, supplier compromise and regulator scrutiny have moved information security from the IT department to the boardroom. Ten days take participants from the clauses of the standard to a management system that works in practice and survives an audit. The first week covers context, scope, leadership commitment, information security policy, asset inventories, risk assessment and treatment, the Statement of Applicability and the control themes of Annex A, including access control, cryptography, operations security and supplier relationships.
The second week goes deeper: incident response, business continuity, cloud and mobile security, vulnerability and patch management, privacy alignment, security metrics, internal audit technique and the management review. Participants then prepare for the certification audit, write nonconformity reports, plan corrective action and build a continual improvement cycle. The programme is aimed at information security managers, CISOs, IT managers, risk and compliance officers, internal auditors, data protection officers and consultants in banks, telecoms, government, health and technology companies. Delivery is classroom, online or in-house, with a CPD-accredited certificate. Afterwards you can lead an ISMS implementation, draft core documentation and conduct an internal audit against the standard.
Organisations in every sector now depend on digital systems for revenue, service delivery and trust. Customers, regulators, lenders and tender evaluators increasingly ask for evidence that information is protected by a managed system rather than by a collection of tools. ISO/IEC 27001 is the best-known international standard for such a system, and recognised certification is a frequent requirement in banking, outsourcing, cloud and public sector contracts.
This ten-day programme gives participants a full working understanding of the standard and the governance behind it. The first five days build the management system: understanding context and interested parties, setting scope, gaining leadership support, assessing and treating risk, selecting controls, writing the Statement of Applicability and preparing policies, procedures and records. The second five days focus on operating and proving it, with deeper technical and organisational controls, incident handling and resilience, performance measurement, internal audit and the certification process.
Compliance is treated as an ongoing discipline. Participants consider how the system interacts with data protection obligations, supplier contracts and sector regulations, and how to keep documentation proportionate. Teaching is lab and workshop based around a case organisation, so that by the end each participant has produced a draft ISMS pack and an audit report and has a roadmap for their own organisation.
On completing the programme, participants will be able to:
Participants leave with a body of practical work, including:
The ten days are structured around the build of one management system for a case organisation:
Day 1: Information Security and the ISO 27001 Framework
Day 2: Context, Leadership and Scope
Day 3: Asset Management and Risk Assessment
Day 4: Risk Treatment and the Statement of Applicability
Day 5: Documentation and Organisational Controls
Day 6: Technical and Physical Controls
Day 7: Secure Operations, Cloud and Change
Day 8: Incident Response and Resilience
Day 9: Performance, Internal Audit and Management Review
Day 10: Certification Readiness and Continual Improvement
The programme is intended for professionals responsible for protecting information and demonstrating compliance, including:
Participants who attend the ten days and complete the practical exercises receive a CPD-accredited Certificate of Completion issued by Vision Reach Global Consultancy. It records training hours and does not replace personal certification by an independent body.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Governance and Compliance in Cybersecurity & Information Security (ISO 27001) programme, you'll be able to interpret the clauses and annex a controls of iso 27001 and relate them to business needs, define isms scope, context and interested party requirements, carry out an information security risk assessment, prepare a risk treatment plan and produce a statement of applicability with justified control selection, and write core policies, procedures and records proportionate to the organisation. The full breakdown of topics is covered session by session in the Course Outline tab above.
The programme is intended for professionals responsible for protecting information and demonstrating compliance, including: Chief information security officers and information security managers, IT managers and systems administrators with security duties, Risk, compliance and governance officers, Internal and IT auditors, Data protection officers and privacy managers, Business continuity and disaster recovery managers, Security consultants preparing clients for certification, Project managers leading ISMS implementation, and Procurement and vendor managers assessing supplier security.
Governance and Compliance in Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Governance and Compliance in Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Governance and Compliance in Cybersecurity & Information Security (ISO 27001) starts October 12, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Governance and Compliance in Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Governance and Compliance in Cybersecurity & Information Security (ISO 27001) Training Course is pitched at advanced professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Governance and Compliance in Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Governance and Compliance in Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →